CVE-2025-13943

Published Feb 24, 2026

Last updated 2 months ago

CVSS high 8.8
Network
Zyxel
Zyxel EX3301-T0

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-13943 is identified as a post-authentication command injection vulnerability affecting specific firmware versions of the Zyxel EX3301-T0 device. This flaw resides within the log file download function of the device's firmware. The vulnerability, categorized under CWE-78 (Improper Neutralization of Special Elements used in an OS Command), allows an authenticated attacker to execute arbitrary operating system commands on the affected device. This is possible due to insufficient neutralization of special characters in user-supplied input within the vulnerable function. The affected firmware versions include those through 5.50(ABVY.7)C0.

Description
A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 could allow an authenticated attacker to execute operating system (OS) commands on an affected device.
Source
security@zyxel.com.tw
NVD status
Analyzed
Products
ee5301-00_firmware, ee3301-00_firmware, dx5401-b1_firmware, dx4510-b1_firmware, dx4510-b0_firmware, dx3301-t0_firmware, dx3300-t1_firmware, dx3300-t0_firmware, ee6510-10_firmware, emg3525-t50b_firmware, emg5523-t50b_firmware, ex2210-t0_firmware, ex3300-t0_firmware, ex3300-t1_firmware, ex3301-t0_firmware, ex3500-t0_firmware, ex3501-t0_firmware, ex3510-b0_firmware, ex3510-b1_firmware, ex3600-t0_firmware, ex5401-b1_firmware, ex5510-b0_firmware, ex5512-t0_firmware, ex5601-t0_firmware, ex5601-t1_firmware, ex7501-b0_firmware, ex7710-b0_firmware, gm4100-b0_firmware, pm7500-00_firmware, vmg3625-t50b_firmware, vmg4005-b50a_firmware, vmg4005-b60a_firmware, ax7501-b1_firmware, pe3301-00_firmware, pe5301-01_firmware, pm3100-t0_firmware, pm5100-t0_firmware, pm5100-t1_firmware, pm7300-t0_firmware, px3321-t1_firmware, px5301-t0_firmware, vmg8623-t50b_firmware, we3300-00_firmware, wx3100-t0_firmware, wx3401-b1_firmware, wx5600-t0_firmware, wx5610-b0_firmware, dm4200-b0_firmware, we4600-00_firmware, emg6726-b10a_firmware, am7510-00_firmware, vmg4927-b50a_firmware

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

security@zyxel.com.tw
CWE-78

Social media

Hype score
Not currently trending
  1. CVE-2025-13943 (CVSS:8.8, HIGH) is Analyzed. A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware ..https://t.co/0y3NXMGyHq #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    1 Mar 2026

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2025-13943 (CVSS:8.8, HIGH) is Analyzed. A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware ..https://t.co/0y3NXMGyHq #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    28 Feb 2026

    51 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Organizations using Zyxel products should prioritize installing the recommended patches and consider replacing any legacy devices that are no longer supported or have reached end-of-life status (CVE-2025-13943, CVE-2026-1459, CVE-2024-40891). https://t.co/KweePUxaRH

    @eclypsium

    27 Feb 2026

    94 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. ⚠️ Vulnerabilidades en productos Zyxel ❗ CVE-2026-1459 ❗ CVE-2025-13943 ❗ CVE-2025-13942 ➡️ Más info: https://t.co/46G5AlbX0D https://t.co/Mm5XqgBCoc

    @CERTpy

    27 Feb 2026

    79 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Zyxel has published 2 CVEs for some vulns I found :D CVE-2025-13943: Authenticated command injection in log export CGI CVE-2025-13942: Unauthenticated command injection in UPnP daemon I will blog about this in the coming months. Meanwhile, exploits here: https://t.co/CbVHekdN5q

    @hacefresko

    24 Feb 2026

    2068 Impressions

    13 Retweets

    37 Likes

    9 Bookmarks

    1 Reply

    0 Quotes

  6. CVE-2025-13943 A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 could allow an… https://t.co/oynISNqseG

    @CVEnew

    24 Feb 2026

    41 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. [CVE-2025-13943: HIGH] Critical cyber security alert: Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 are vulnerable to command injection, enabling attackers to run OS commands.#cve,CVE-2025-13943,#cybersecurity https://t.co/UloRAYwlkg

    @CveFindCom

    24 Feb 2026

    46 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

Configurations